New Writeup❗️
Date: Sat, 25 Dec 2021 14:11:16 GMT
Title: Massive Users Account Takeovers(Chaining Vulnerabilities to IDOR)
Link: https://medium.com/p/ea4e1b6407d2
Date: Sat, 25 Dec 2021 14:11:16 GMT
Title: Massive Users Account Takeovers(Chaining Vulnerabilities to IDOR)
Link: https://medium.com/p/ea4e1b6407d2
Medium
Massive Users Account Takeovers(Chaining Vulnerabilities to IDOR)😲
Hello hunters 👋✌ this is my 7th writeup 🧾,
New Writeup❗️
Date: Wed, 03 Nov 2021 17:35:05 GMT
Title: HacktoberFest2k21 vulnerability: How users metadata can be changed via Auth JWT tokens leaking from…
Link: https://medium.com/p/3028f8ad6991
Date: Wed, 03 Nov 2021 17:35:05 GMT
Title: HacktoberFest2k21 vulnerability: How users metadata can be changed via Auth JWT tokens leaking from…
Link: https://medium.com/p/3028f8ad6991
Medium
HacktoberFest2k21 vulnerability: How users metadata can be changed via Auth JWT tokens leaking from…
Hello Awesome readers 👨💻✌✌,
New Writeup❗️
Date: Tue, 05 Oct 2021 13:42:12 GMT
Title: Easy Premium Account Access and Admin role escalation via Object manipulation in the server…
Link: https://medium.com/p/619d325ab66
Date: Tue, 05 Oct 2021 13:42:12 GMT
Title: Easy Premium Account Access and Admin role escalation via Object manipulation in the server…
Link: https://medium.com/p/619d325ab66
Medium
Easy Premium Account Access and Admin role escalation via Object manipulation in the server…
Hey infosec Geeks ✌,
New Writeup❗️
Date: Tue, 21 Sep 2021 14:39:10 GMT
Title: Cookie Stealing via Clickjacking using Burp collaborator
Link: https://medium.com/p/ff6f4ac1c18b
Date: Tue, 21 Sep 2021 14:39:10 GMT
Title: Cookie Stealing via Clickjacking using Burp collaborator
Link: https://medium.com/p/ff6f4ac1c18b
Medium
Cookie Stealing via Clickjacking using Burp collaborator
Hello 👋 infosec geeks 👨💻 this is my 4th blog post,
New Writeup❗️
Date: Thu, 19 Aug 2021 09:00:36 GMT
Title: HTML Injection via user agent leads to website distortion revealing backend code.
Link: https://medium.com/p/304fee8f211c
Date: Thu, 19 Aug 2021 09:00:36 GMT
Title: HTML Injection via user agent leads to website distortion revealing backend code.
Link: https://medium.com/p/304fee8f211c
Medium
HTML Injection via user agent leads to website distortion revealing backend code.
Hello Awesome readers,
New Writeup❗️
Date: Wed, 11 Aug 2021 08:07:52 GMT
Title: How Github Dork Help me to Access Full FTP server
Link: https://medium.com/p/4d71da3171b4
Date: Wed, 11 Aug 2021 08:07:52 GMT
Title: How Github Dork Help me to Access Full FTP server
Link: https://medium.com/p/4d71da3171b4
Medium
How Github Dork Help me to Access Full FTP server
Hello cybersecurity geeks,
New Writeup❗️
Date: Wed, 11 Aug 2021 06:49:19 GMT
Title: Reset password Token led to account takeover
Link: https://medium.com/p/19e5eb3cf816
Date: Wed, 11 Aug 2021 06:49:19 GMT
Title: Reset password Token led to account takeover
Link: https://medium.com/p/19e5eb3cf816
Medium
Reset password Token led to account takeover
Hello cybersecurity geeks,
New Writeup❗️
Date: Sun, 14 Feb 2021 08:41:37 GMT
Title: How I Hacked Everyone’s Resume/CV’s and Got €€€
Link: https://medium.com/p/851aaa4d75d9
Date: Sun, 14 Feb 2021 08:41:37 GMT
Title: How I Hacked Everyone’s Resume/CV’s and Got €€€
Link: https://medium.com/p/851aaa4d75d9
Medium
How I Hacked Everyone’s Resume/CV’s and Got €€€
Hello Members, I am Vishal Bharad. Works as Penetration Tester and from India.
New Writeup❗️
Date: Sun, 14 Feb 2021 06:11:42 GMT
Title: Stored XSS in icloud.com — $5000
Link: https://medium.com/p/998b8c4b2075
Date: Sun, 14 Feb 2021 06:11:42 GMT
Title: Stored XSS in icloud.com — $5000
Link: https://medium.com/p/998b8c4b2075
Medium
Stored XSS in icloud.com — $5000
Hello Guys hope you all are doing well, fine and healthy during this hard time.
New Writeup❗️
Date: Sat, 21 Mar 2020 09:07:05 GMT
Title: Account Takeover Via Modifying Email ID — Codeigniter Framework
Link: https://medium.com/p/ca30741ad297
Date: Sat, 21 Mar 2020 09:07:05 GMT
Title: Account Takeover Via Modifying Email ID — Codeigniter Framework
Link: https://medium.com/p/ca30741ad297
Medium
Account Takeover Via Modifying Email ID — Codeigniter Framework
Hello Members, I am Vishal Bharad. Works as Security Researcher and pursuing OSCP. Here I am Back with another Interesting blog on Full…
New Writeup❗️
Date: Mon, 10 Feb 2020 08:25:46 GMT
Title: Stored XSS on Angular JS 1.4.9
Link: https://medium.com/p/b2f6121d8c59
Date: Mon, 10 Feb 2020 08:25:46 GMT
Title: Stored XSS on Angular JS 1.4.9
Link: https://medium.com/p/b2f6121d8c59
Medium
Stored XSS on Angular JS 1.4.9
Introduction :
New Writeup❗️
Date: Mon, 03 Feb 2020 14:09:12 GMT
Title: (Improper Access Control) Vulnerability In Prototype 1.6.0.1 Framework.
Link: https://medium.com/p/379cc3a05079
Date: Mon, 03 Feb 2020 14:09:12 GMT
Title: (Improper Access Control) Vulnerability In Prototype 1.6.0.1 Framework.
Link: https://medium.com/p/379cc3a05079
Medium
(Improper Access Control) Vulnerability In Prototype 1.6.0.1 Framework.
Introduction :
New Writeup❗️
Date: Mon, 23 Dec 2019 05:56:53 GMT
Title: 2 FA Bypass via CSRF Attack
Link: https://medium.com/p/8f2f6a6e3871
Date: Mon, 23 Dec 2019 05:56:53 GMT
Title: 2 FA Bypass via CSRF Attack
Link: https://medium.com/p/8f2f6a6e3871
Medium
2 FA Bypass via CSRF Attack
Introduction :
New Writeup❗️
Date: Sat, 21 Dec 2019 10:03:08 GMT
Title: Full Account Takeover (Android Application)
Link: https://medium.com/p/78fa922f78c5
Date: Sat, 21 Dec 2019 10:03:08 GMT
Title: Full Account Takeover (Android Application)
Link: https://medium.com/p/78fa922f78c5
Medium
Full Account Takeover (Android Application)
Introduction :
New Writeup❗️
Date: Thu, 19 Dec 2019 10:17:08 GMT
Title: Account Takeover Through Password Reset Poisoning
Link: https://medium.com/p/72989a8bb8ea
Date: Thu, 19 Dec 2019 10:17:08 GMT
Title: Account Takeover Through Password Reset Poisoning
Link: https://medium.com/p/72989a8bb8ea
Medium
Account Takeover Through Password Reset Poisoning
Introduction :
New Writeup❗️
Date: Sat, 18 Feb 2023 09:17:11 GMT
Title: Found an URL in the android application source code which lead to an IDOR
Link: https://medium.com/p/1b8768708756
Date: Sat, 18 Feb 2023 09:17:11 GMT
Title: Found an URL in the android application source code which lead to an IDOR
Link: https://medium.com/p/1b8768708756
Medium
Found an URL in the android application source code which lead to an IDOR
I was testing the target which had its web application and mobile application in scope. Let’s say the target is example.com
New Writeup❗️
Date: Sat, 16 Jul 2022 14:26:56 GMT
Title: Authorization token leak from verify email endpoint
Link: https://medium.com/p/f28803476680
Date: Sat, 16 Jul 2022 14:26:56 GMT
Title: Authorization token leak from verify email endpoint
Link: https://medium.com/p/f28803476680
Medium
Authorization token leak from verify email endpoint
While testing a website I found that the verify email endpoint was leaking the authorization tokens of any verified users by just passing…
New Writeup❗️
Date: Thu, 17 Jun 2021 17:50:28 GMT
Title: Recon Step/ Methodology
Link: https://medium.com/p/c9664f5ce312
Date: Thu, 17 Jun 2021 17:50:28 GMT
Title: Recon Step/ Methodology
Link: https://medium.com/p/c9664f5ce312
Medium
Recon Step/ Methodology
This is just a self-note on different steps to perform while approaching a target.
New Writeup❗️
Date: Mon, 13 Sep 2021 09:23:40 GMT
Title: Reflected XSS on Byjus(My first bug)
Link: https://medium.com/p/a5bbab098748
Date: Mon, 13 Sep 2021 09:23:40 GMT
Title: Reflected XSS on Byjus(My first bug)
Link: https://medium.com/p/a5bbab098748
Medium
Reflected XSS on Byjus(My first bug)
Around a year back, schools had started to implement an online mode of learning. I had to complete my chemistry assignment and was too lazy…
New Writeup❗️
Date: Sat, 19 Jun 2021 09:14:41 GMT
Title: Tech_Supp0rt: 1 (VulnHub)
Link: https://medium.com/p/16486c93205e
Date: Sat, 19 Jun 2021 09:14:41 GMT
Title: Tech_Supp0rt: 1 (VulnHub)
Link: https://medium.com/p/16486c93205e
Medium
Tech_Supp0rt: 1 (VulnHub)
This is the first CTF machine I built which is now live on VulnHub. The difficulty is Easy and can be solved by anyone with basic…